Data Processing Addendum & sub-processors
Last updated: 3 October 2026
When you use AdForge for your business and your brand data contains personal data (for example customer testimonials), we process it as your processor under Art. 28 GDPR. This addendum forms part of our Terms of Service.
1. Scope and instructions
We process personal data only to provide the Service and on your documented instructions, which are given through your use of the Service and these terms. Categories of data subjects may include your customers, reviewers and staff named on your website; categories of data are names, quotes, images and other content you submit.
2. Our obligations
- Persons authorised to process the data are bound by confidentiality.
- We implement appropriate technical and organisational measures (see Privacy Policy, section Security).
- We assist you with data-subject requests and data-protection impact assessments where reasonably required.
- We notify you without undue delay, and where possible within 48 hours, after becoming aware of a personal data breach affecting your data.
- On termination we delete your data within 30 days, unless retention is required by law.
- We make available information necessary to demonstrate compliance and allow reasonable audits, normally by providing documentation.
3. Sub-processors
You authorise us to engage the sub-processors listed below. We impose data-protection obligations on them equivalent to this addendum. We will announce new sub-processors on this page at least 14 days before they start processing, and you may object on reasonable grounds.
Current sub-processors
| Sub-processor | Purpose | Location | Transfer safeguard |
|---|---|---|---|
| Anthropic, PBC (Claude) | AI text generation: brand analysis, angles, ad copy, strategy | United States | Standard Contractual Clauses; no training on customer data |
| Google LLC / Google Cloud (Gemini) | AI image generation and editing; Google sign-in (optional) | EU / United States | EU–US Data Privacy Framework, Standard Contractual Clauses |
| Stripe Payments Europe, Ltd. | Subscription billing and payment processing | Ireland (EU) / United States | EU–US Data Privacy Framework, Standard Contractual Clauses |
| Cloudflare, Inc. | Hosting edge, CDN, DDoS protection, Turnstile bot protection, R2 object storage for generated images | Global network; EU storage where available | EU–US Data Privacy Framework, Standard Contractual Clauses |
| Amazon Web Services EMEA SARL (Amazon SES) or Resend, Inc. | Transactional email delivery (verification, password reset) | EU (Ireland) / United States | EU–US Data Privacy Framework, Standard Contractual Clauses |
Questions about this document? Email [email protected].